Method for determining a robust prediction and a certification interval associated with a regression task
By modifying a pre-trained model to generate median predictions from noisy data and adding certification intervals, the method addresses adversarial attacks, enhancing robustness and reducing complexity in prediction models.
Patent Information
- Application Number
- EP2025153041
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-24
- Filing Date
- 2025-01-21
- Publication Date
- 2025-07-30
AI Technical Summary
Existing automatic prediction models, particularly artificial neural networks, are vulnerable to adversarial attacks that subtly alter input data to degrade predictions, posing critical security risks in applications like autonomous vehicles and medical imaging.
A method is introduced to modify a pre-trained prediction model by generating a robustified prediction equal to the median value of the distribution of predictions from noisy training data, supplemented with additional branches to predict certification intervals, ensuring the model's robustness and providing a robustness indicator.
The method enhances the model's resistance to adversarial attacks while reducing complexity and execution costs, ensuring predictions remain close to the median value and providing a certification interval for robustness assurance.
Smart Images

Figure IMGAF001_ABST
Abstract
Description
[0001] The invention relates to the field of automatic learning methods for regression or prediction tasks, in particular artificial intelligence methods involving artificial neural networks. The invention relates in particular to applications for detecting and tracking objects in a sequence of images which aim to predict the position of an object of a given class of objects (for example, an individual, a vehicle) in an image or a sequence of images. The invention finds particular application in the field of driving autonomous vehicles or in the field of medical applications involving the detection of objects in medical images or in the field of video surveillance or for the detection of three-dimensional objects from 3D images or three-dimensional camera pose calculations.Application areas also include facial landmark detection for face recognition or super-resolution.
[0002] In general, the invention can be applied to any regression task which covers all statistical analysis methods which make it possible to approach a variable from other variables which are correlated with it.
[0003] The invention is advantageously applied in the context of supervised learning methods for which the training data is labeled. The invention applies, for example, to the prediction of meteorological variables such as temperature, humidity or air viscosity. It also applies to the prediction of energy reserves, the prediction of a biological age from health data or even to the prediction of forces exerted on a mechanical structure from data from sensors.
[0004] More specifically, the invention relates to determining an improved prediction model that is robust to adversarial attacks and also produces an indicator of robustness of the generated prediction to adversarial attacks.
[0005] For example, the values predicted by the model are the coordinates of the corners of a bounding box associated with an object detected in an image. In general, the invention can be applied to any data predicted via a regression task learned by a pre-trained artificial intelligence model.
[0006] Artificial intelligence models, particularly artificial neural networks, are tools that can be used to solve regression tasks to predict the evolution of certain data.
[0007] However, there is a general security problem for these models in the face of so-called adversarial attacks which aim to disrupt the model to distort the predictions generated without this being detectable by a user.
[0008] In other words, an adversarial attack consists of slightly modifying the input data, in a way that is imperceptible to a user, but in such a way as to degrade the predictions generated by the model. This type of attack is difficult to avoid since the model's input data can be altered by a third party. This vulnerability of prediction models can lead to critical security issues in areas where high prediction accuracy is desired. This is particularly the case in the field of predicting a vehicle trajectory or identifying the position of an obstacle for applications related to autonomous vehicles that involve consequences for the safety of individuals.
[0009] There are different types of adversarial attacks that can impact the reliability of a learning model's predictions. While not exhaustive, four examples of methods for generating adversarial attacks can be cited.
[0010] Reference [1] describes a first example of a method called FGSM or "Fast Gradient Sign Method" in English. It concerns a fast method for modifying input data of an automatic prediction model. The method is described in the context of image data. The proposed attack uses the gradient of the cost function to determine a direction in which the pixel intensities must be modified to generate the most effective perturbation without visually altering the image.
[0011] The image pixels are modified by adding a residual value that depends on the gradient of a cost function.
[0012] Reference [2] describes a variant of the FGSM method that proposes an iterative approach in calculating the alterations added to the pixels.
[0013] Reference [3] describes a generalization of the previous method with an initialization of the perturbation from a uniform distribution.
[0014] Reference [4] lists other types of adversarial attacks including the Carlini and Wagner method which is based on a search for the optimal perturbation via a criterion to be optimized.
[0015] Generally speaking, all adversarial attack methods are based on adding perturbations to the input data in such a way as to limit the visual or cognitive impact on the data while degrading the model's predictions.
[0016] There is therefore a need to develop methods of defense against adversarial attacks which aim to make automatic prediction models more robust against these attacks and / or to certify that the predictions provided by these models are not impacted by such attacks.
[0017] There are two types of methods to make an automatic prediction or regression model more robust to adversarial attacks.
[0018] The first method, described in reference [5], is based on the use of adversarial examples generated from the training data to locally make the model more robust on this training data. An adversarial example is a training data modified by adding a small perturbation such that the prediction provided by the model from the modified training data is different from the prediction obtained from the unmodified training data. In other words, this method consists of augmenting the training dataset with modified data of the same order of magnitude as data generated via adversarial attacks. In this way, the model learns to better distinguish altered data from original data and to provide correct predictions even for altered data.
[0019] A disadvantage of this type of method is that the model's accuracy can be degraded due to training on corrupted data. Furthermore, a model trained using this method can always be attacked by a more powerful adversarial attack. Finally, this method has the disadvantage of increasing the model's training time.
[0020] A second method, called regularization, is described in reference [6]. This method aims to penalize the propagation of noise through the neural network by minimizing the quantity ∥ f i ( x + d ) - f i ( x )∥ p where x is the training data, d is the added disturbance of low value, f i is the model to be robustified and ∥ ∥ p is an I p norm. This constraint can be added as an optimization constraint when training the model f iin order to make it more robust to the impacts of alterations to the data.
[0021] A disadvantage of regularization methods is that they are complicated to implement for high-dimensional data (e.g., for super-resolution applications). Moreover, the aforementioned optimization problem is not always easy to solve in practice.
[0022] In addition to methods that aim to make the regression model more robust to adversarial attacks, there are so-called certification methods that aim to certify the robustness of a model.
[0023] A first example of a certification method concerns methods based on Lipschitz-type networks (for example described in reference [7]). This method proposes to define a robustness radius proportional to the inverse of the constant of the Lipschitz neural network. Alterations whose value is lower than this radius do not lead to degradation of the predictions generated by the model.
[0024] A disadvantage of this method is that it is limited to models performing classification tasks and Lipschitz-type neural networks.
[0025] Another example of a certification method is described in references [8] and [9]. This other method is applicable to both classification and regression tasks. Reference [9] describes the determination of a certification interval for a prediction task. The boundaries of the interval are determined from a Monte Carlo method applied to estimate quantiles of the prediction values. Predictions are generated from noisy data using Gaussian noise.
[0026] This method has the disadvantage of requiring a very large amount of noisy data to estimate the values of the certification limits with sufficient precision. This implies a significant execution cost for inference due to the use of the Monte Carlo method.
[0027] A new method for improving the robustness of an automatic regression model is proposed which does not have the disadvantages of the aforementioned prior art methods.
[0028] The invention is based on modifying a pre-trained prediction model so as to provide a more attack-robust prediction that is equal to the median value of the distribution of prediction values possible in the event of tampering with the input data.
[0029] The invention also makes it possible to produce a certification interval for each generated prediction value.
[0030] The invention has the advantage of a reduction in complexity compared to the Monte Carlo method.
[0031] The subject of the invention is a method, implemented by computer, for training a model for automatic prediction of a physical quantity, the method comprising the steps of: Receive an initial automatic prediction model of said quantity, Receive a training data set, Generate a noisy training data set by adding a randomly drawn noise value to each data item in the training data set, For each data item in the noisy training data set, run the initial automatic prediction model to determine a main prediction of the physical quantity, Modify the initial model by replacing the main prediction of the physical quantity with a robustified prediction, Train the modified model from the noisy training data set so that the robustified prediction is equal to a median value of the distribution of the main prediction values provided by the initial model from the noisy training data set.
[0032] In an alternative embodiment, the method according to the invention further comprises the steps of: Supplement the initial model to further predict at least two certification values defining the bounds of at least one certification interval of the robustified prediction, Train the supplemented model from the noisy training dataset such that each predicted certification value is equal to a quantile value of the distribution of the main prediction values provided by the initial model from the noisy training dataset.
[0033] According to a particular aspect of the invention, the difference between the two quantile values depends on a predefined maximum value of a radius of an adverse attack applied to the training data.
[0034] According to a particular aspect of the invention, the initial model comprises a main prediction branch of the physical quantity and the completed model further comprises at least one additional prediction branch trained to predict the certification values.
[0035] According to a particular aspect of the invention, the second quantile value is equal to one minus the first quantile value.
[0036] According to a particular aspect of the invention, the modified model is trained by minimizing a quantile loss function depending on the difference between a prediction of the physical quantity provided by the initial model from the noisy training data set and, respectively, the robustified prediction and each respective prediction of a certification value provided by the modified model.
[0037] According to a particular aspect of the invention, the quantile loss function is defined by the following relationship: ρ y − y ^ τ = τ y − y ^ si y − y ^ ≥ 0 τ − 1 y − y ^ sinon t is a quantile value between 0 and 1, y is a prediction of the physical quantity provided by the initial model from the noisy training data set, ŷ is the robustified prediction or a prediction of a certification value provided by the modified model.
[0038] According to a particular aspect of the invention, the initial model is pre-trained on a first set of training data and the set of noisy training data is obtained by duplicating each data of the first set several times and adding to each data a randomly drawn noise value.
[0039] According to a particular aspect of the invention, the initial model is pre-trained on the noisy training data set.
[0040] According to a particular aspect of the invention, the initial model comprises a first part trained to extract a set of characteristics from the input data and a second part comprising at least one prediction branch.
[0041] According to a particular aspect of the invention, the second part of the modified model comprises a main prediction branch for predicting a robustified prediction of said physical quantity and at least one additional prediction branch of the certification values of said physical quantity, the training parameters of the prediction branches of the modified model being initialized to the training parameters of the main prediction branch of the initial model.
[0042] According to a particular aspect of the invention, the training data are sets of images and the physical quantity is a position of an object in an image.
[0043] According to a particular aspect of the invention, the initial model is trained to detect an object in an image and to predict the coordinates of a box bounding the object.
[0044] The invention also relates to a method, implemented by computer, for automatic prediction of a physical quantity comprising the execution of the modified automatic prediction model, trained using the training method according to the invention, so as to determine a robustified prediction of said physical quantity and at least two certification values of said physical quantity defining at least one certification interval of said prediction against an adverse attack.
[0045] In an alternative embodiment, the method for automatically predicting a physical quantity comprises the prediction of several pairs of certification values and the selection of the certification interval having the smallest width and respecting an order relationship such that: the prediction of the lower limit of the certification interval is lower than the prediction of the physical quantity itself lower than the prediction of the upper limit of the certification interval.
[0046] In an alternative embodiment, the method for automatically predicting a physical quantity comprises providing a robustness indicator of the robustified prediction to said adverse attack, the robustness indicator being inversely proportional to the width of the certification interval.
[0047] According to a particular aspect of the invention, the physical quantity is a position of an object in an image and the training data are sets of images.
[0048] The invention also relates to a device for automatic prediction of a physical quantity comprising a calculation unit configured to execute the steps of the method according to the invention and a display interface for displaying the results of the method.
[0049] The invention also relates to a computer program comprising code instructions for implementing one of the methods of the invention, when said program is executed on a computer, as well as a computer-readable recording medium on which the computer program according to the invention is recorded.
[0050] Other features and advantages of the present invention will become more apparent upon reading the following description in relation to the following appended drawings. [ Fig. 1 ] represents a diagram of an example of a pre-trained machine learning model architecture to perform a regression task, [ Fig. 2 ] represents a diagram of a task-specific module of the regression architecture of the figure 1 , [ Fig. 3a ] represents an architectural diagram of the model of the figure 2 modified according to a first embodiment of the invention, [ Fig. 3b ] represents a diagram of the modified model of the figure 3a , supplemented with two additional prediction branches to determine a certification interval of the main prediction according to another embodiment of the invention, [ Fig. 4 ] represents a flowchart detailing a training method by fine-tuning the modified model of the figure 3aaccording to one embodiment of the invention, [ Fig. 5 ] represents an example of application of the invention to the detection of objects in an image,
[0051] The invention consists, starting from an artificial intelligence model possibly trained or pre-trained to carry out a task of regression or prediction of a value, in modifying this model to make the prediction more robust against adversary attacks. In a particular embodiment, the invention also consists in completing the model then training the completed model to add at least two additional predictions corresponding to the two limits of at least one certification interval associated with the prediction. The size of the certification interval is used to determine a robustness indicator of the modified model.
[0052] In a particular embodiment of the invention, the new training is a fine tuning which consists of training an already pre-trained model by modifying only part of the parameters.
[0053] Although the invention is described below in the context of a specific example applied to autonomous driving and which concerns a pre-trained model for performing object detection in an image with prediction of the coordinates of a box encompassing each object, the invention is not limited to this application or to this particular example and can be applied to any regression task aimed at predicting the evolution of a data item or a variable, for example any characteristic value of a position of an object in an image. The possible applications are not limited to autonomous driving but can extend to the fields of medical imaging, telemedicine or video surveillance for which a similar need for detecting and localizing objects in an image exists.In general, the invention applies to any task of predicting a physical quantity taken from the following quantities: a position of an object in an image, a meteorological quantity such as the temperature, humidity or viscosity of the air, an energy measurement, a quantity measured by a sensor.
[0054] There figure 4 details the steps for implementing the method according to the invention. It begins at step 401 with the reception of a learning model of a prediction task associated with a training data set on which the model has been pre-trained.
[0055] Alternatively, the invention can also be applied to directly carry out the initial training of the model, in this case the model received in step 401 is not pre-trained, it is initialized with random parameters.
[0056] There figure 1represents a general diagram of such a model, which can take the form of an artificial neural network comprising several interconnected convolution layers. Generally speaking, the network comprises a first sub-network called "backbone" BB_N which aims to extract relevant characteristics from the data X received as input to convert them into a reduced-dimensional space. The model training process is supervised, the data X are therefore accompanied by a label or annotation Y which gives the real value of the information that the model aims to predict. The network then comprises one or more modules R_N 1 ,R_N 2 ,R_N m dedicated to the tasks of regression or prediction of the value of Y from the data X.
[0057] For example, the input data X are images and the variable to be predicted concerns the coordinates of a rectangular bounding box centered on an object to be detected such as an individual.
[0058] The different prediction branches R_N 1 ,R_N 2 ,R_N m are for example trained to provide several predictions y 1 ∧ , y 2 ∧ , y m ∧ coordinates of a bounding box aligned to different resolutions of a grid superimposed on the image. More generally, a single prediction branch may be sufficient.
[0059] There figure 2 represents a more detailed diagram of an example R_N module corresponding to a prediction branch of the global model.
[0060] The R_N module receives as input the characteristics extracted by the backbone network BB_N. In the example of the figure 2 , the R_N module has a prediction branch and a classification branch, for example to associate a class with a detected object. The classification branch can be optional.
[0061] Each branch consists of several neural networks comprising several interconnected convolution layers CONV1, CONV2, CONV3 according to model-specific architectures and settings. The neural network architectures of the two prediction and classification branches can be identical or different.
[0062] The first prediction branch 200 is trained via the optimization, for example the minimization, of a first cost function L1 with respect to the parameters of the model. The second classification branch 201 is trained via the optimization of a second cost function L2.
[0063] Training methods can be based on gradient backpropagation techniques or any other suitable techniques that are part of general domain knowledge and are not described in detail here.
[0064] The model described in figures 1 and 2is pre-trained on a first set of training data to perform the prediction and classification tasks described above. As indicated in the preamble, such a model is likely to be sensitive to adversarial attacks leading to potential degradation of predictions. Furthermore, this model does not provide any information to certify the level of robustness of the model to such attacks.
[0065] To resolve these drawbacks, it is proposed to modify the initial model described in figure 1 to make it more robust against enemy attacks.
[0066] There figure 3a describes the modified model R'_N according to a first embodiment of the invention.
[0067] The R'N model is designed from the initial R_N model, possibly pre-trained. Only the prediction branch 300 is modified compared to the prediction branch 200 of the initial model. This new prediction branch has the same convolution layers, in other words the same architecture, but it is optimized via the optimization of a new L3 cost function which will be described later.
[0068] Training the modified model R'_N makes it possible to generate a prediction of the same nature as the initial model but which is more robust to adversary attacks.
[0069] There figure 4 describes the method of training the modified model R'_N according to one embodiment of the invention.
[0070] In step 401, the initial model R_N is pre-trained and the parameters obtained for the classification branch 201 are fixed. According to another embodiment, the model received in step 401 is not pre-trained in this case its parameters are initialized to predefined values.
[0071] In the case where the initial model is pre-trained, the method continues at step 402. The first training data set used to train the initial model R_N is augmented, for example by duplicating each image of the first set a number M of times, where M is an integer at least equal to 2. This produces a second augmented training data set.
[0072] In step 403, a randomly drawn noise value is applied to each pixel of each image of the second set to generate a third set of noisy training data. Thus, the third set includes several versions of each perturbed image with different noise distributions.
[0073] According to another embodiment, the initial model R_N is pre-trained on the same noisy data as those obtained in step 403. Alternatively, the noise level applied to the data to pre-train the initial model R_N is different from that applied in step 403, for example, it is lower or it varies gradually from a zero value to a value corresponding to the noise level applied in step 403.
[0074] Random noise is for example a white Gaussian noise of predetermined variance but can be a random noise drawn according to another distribution.
[0075] The purpose of operation 403 is to noise the data in order to generate a distribution of data values with a standard deviation of the order of the noise level. The variance of the added noise is for example between 10 -3< and 10 -1< considering that the value of the pixels is normalized between 0 and 1.
[0076] In step 404, the initial model is executed for all the noisy data of the third set produced in step 403. For each image, a prediction is obtained y p ^ coordinates of each bounding box, or more generally a prediction of the position of an object in the image.
[0077] In step 405, the modified model R'_N (or only the new prediction branch 300) is trained by fine-tuning, using the third set of noisy augmented data so as to predict a new prediction value. y p , m ^ more robust. In a particular embodiment, the values of the hyper-parameters of the new prediction branch are initialized to the same values as those of the initial prediction branch 200.
[0078] The new prediction branch 300 is trained via the minimization of a particular loss function or cost function.
[0079] This cost function is given by the following relation: ρ u τ = τ . u si u ≥ 0 τ − 1 . u sinon
[0080] Minimizing the cost function r ( u ) t For u = y p ^ − y p , m ^ And t =0.5 makes the new prediction y p , m ^ which minimizes this function is equal to the quantile of order t = 0.5 of the distribution of y values. This property is notably demonstrated in reference
[10] . Thus, the new prediction y p , m ^ provided by the modified model corresponds to the quantile of order 0.5 of the distribution of the values of the prediction y.
[0081] The 0.5th order quantile corresponds to the median value of this distribution. The new prediction y p , m ^ is therefore guaranteed to correspond to the median value of the distribution of predictions regardless of the variations undergone by the input data. In this way, it is ensured that, even in the event of an adverse attack, the prediction will remain close to the median value of the predictions obtained in the absence of an attack and will not deviate significantly from this median value. Conversely, when the input data are not altered, the median prediction y p , m ^ is substantially identical to the prediction provided by the initial model.
[0082] In a particular embodiment of the invention, the modified model R'_N is further supplemented by the addition of at least two additional prediction branches 301,302 as shown diagrammatically in figure 3b .
[0083] These two prediction branches are similar to the main prediction branch 300 in that they comprise several neural networks comprising several interconnected convolution layers CONV1,1; CONV1,2; CONV1,3; CONV2,1; CONV2,2; CONV2,3. Each of the additional prediction branches 301,302 is trained via the optimization of a particular cost function L3,1; L3,2 which will be described in more detail later.
[0084] The two additional predictions correspond to the boundaries of a certification interval around the main prediction. This certification interval makes it possible to certify that the main prediction is always contained in this interval.
[0085] The training of each of the additional prediction branches 301,302 is carried out via the same training method described in figure 4 already used for the main prediction 300, except that the quantile value of the cost function is different.
[0086] In a first embodiment, this quantile value is determined based on the maximum radius of an adversary attack against which the modified model must be robust.
[0087] The quantile value inf is taken in the interval ]0 ; 0.5[ for the prediction of the lower bound of the certification interval and is taken at the value t sup = 1 - inf for the prediction of the upper bound of the interval.
[0088] According to an exemplary embodiment, the two quantile values are taken respectively equal to τ inf = ϕ − ε σ And τ sup = ϕ ε σ , with ε the maximum radius of the opposing attack and σ the standard deviation of the noise added to the data at step 403.
[0089] Φ is the distribution function of a reduced centered normal law between 0 and 1.
[0090] The trained model of the figure 3b generates a prediction of a certification interval of the main prediction. In other words, this model makes it possible to certify that the value of the main prediction always varies in the certification interval even in the event of an adverse attack with a maximum radius equal to ε.
[0091] In an alternative embodiment of the invention, a robustness indicator is provided by the model R'_N so as to quantify the level of robustness of the model to adversary attacks. This robustness indicator is inversely proportional to the width of the certification interval. In other words, if the certification interval is wide, this means that in the event of an adversary attack, the prediction can vary within a wide range of variations, which means that the model is not very robust. Conversely, if the certification interval is narrow, this reflects a significant robustness of the model to adversary attacks.
[0092] In another embodiment of the invention, the maximum radius of the adversary attack is not known, in this case, the R'_N model is designed to predict several pairs of different quantile values each corresponding to a different certification interval.
[0093] For example, the lower quantile value is taken equal to a value in the interval ]0; 0.5[ by scanning this interval in regular steps. For example, the variation step is chosen equal to 0.1 or 0.01. Alternatively, the chosen values are not regularly distributed in this interval.
[0094] The different quantile predictions are obtained via several additional prediction branches in which case the model of the figure 3b is completed with as many additional branches as predictions or a single prediction branch generates all additional quantile values directly.
[0095] When the model is run in inference, we check, for each certification interval, whether the order relations are respected for the two limits of the interval and the median main prediction.
[0096] In other words, when the data is not corrupted, we should expect the following ordering relationship to hold: y p , inf ^ < y p , m ^ < y p , sup ^ .
[0097] In case of an adversarial attack with a large attack radius, the order relations for the quantiles closest to the median (i.e. those for which the certification interval has the smallest width) may no longer be respected due to corruption of the predictions.
[0098] In this case, the final certification interval is selected as the interval of smallest width that respects the order relationship between the three predictions above.
[0099] This additional information makes it possible to guarantee a user of the model a given level of robustness.
[0100] There figure 5shows an example of a result obtained by executing the invention for an application of object detection in an image. According to this example, the initial model is trained to predict the coordinates of bounding boxes framing an object, for example a person or an animal (horse or dog in the example of the figure 5 ), the object being otherwise classified via a classification task. Furthermore, the image provided as input to the model was disrupted by an adversary attack.
[0101] There figure 5shows, for each detected object (a person, a dog, a horse), a primary prediction 500 which corresponds to the median robust prediction of the attacked image and two secondary predictions 501,502 corresponding to the limits of the certification interval. The visualization of these two secondary predictions allows the user to determine the level of robustness of the model. In this example, the values of the quantiles for training the secondary prediction branches are set to 0.4 and 0.6 respectively.
[0102] Without departing from the scope of the invention, the different additional prediction branches 301,302 can be replaced by a single prediction branch trained to directly predict the two certification values corresponding to the two limits of the certification interval.
[0103] Alternatively, the two predicted certification values can also be added directly to the main prediction branch 300 without the need to add additional prediction branches to the model.
[0104] The invention can be implemented as a computer program comprising instructions for its execution. The computer program can be recorded on a recording medium readable by a processor.
[0105] Reference to a computer program that, when executed, performs any of the functions described above, is not limited to an application program running on a single host computer. Rather, the terms computer program and software are used herein in a general sense to refer to any type of computer code (e.g., application software, firmware, microcode, or any other form of computer instruction) that can be used to program one or more processors to implement aspects of the techniques described herein. In particular, the computing means or resources may be distributed (" Cloud computing"), possibly using peer-to-peer technologies. The software code may be executed on any suitable processor (e.g., a microprocessor) or processor core or a set of processors, whether provided in a single computing device or distributed among several computing devices (e.g., as may be accessible in the device environment). The executable code of each program enabling the programmable device to implement the processes according to the invention may be stored, for example, in the hard disk or in read-only memory. Generally, the program(s) may be loaded into one of the storage means of the device before being executed.The central unit can control and direct the execution of the instructions or portions of software code of the program(s) according to the invention, instructions which are stored in the hard disk or in the read-only memory or in the other aforementioned storage elements.
[0106] The invention can be implemented on a computing device based, for example, on an embedded processor. The processor can be a generic processor, a specific processor, an application-specific integrated circuit (also known as an ASIC for "Application-Specific Integrated Circuit") or an in situ programmable gate network (also known as an FPGA for "Field-Programmable Gate Array"). The computing device can use one or more dedicated electronic circuits or a general-purpose circuit. The technique of the invention can be carried out on a reprogrammable computing machine (a processor or a microcontroller for example) executing a program comprising a sequence of instructions, or on a dedicated computing machine (for example a set of logic gates such as an FPGA or an ASIC, or any other hardware module). References
[0107] [1] I. Goodfellow, J. Shlens, C. Szegedy. Explaining and harnessing adversarial examples.arXiv preprintarXiv:1412.6572. 2014. [2] A. Kurakin, I. Goodfellow, and S. Bengio. Adversarial examples in the physical world.arXiv preprintarXiv:1607.02533, 2016. [3] A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu,Towards deep learning models résistant to adversarial attacks, arXiv preprint arXiv:1706.06083, 2017. [4] K. Ren, T. Zheng, Z. Qin, and X. Liu, Adversarial attacks and defenses in deep learning, Engineering, vol. 6, no. 3, pp. 346-360, 2020. [5] I. Goodfellow, J. Shlens, C. Szegedy. Explaining and harnessing adversarial examples.arXiv preprintarXiv:1412.6572. 2014. [6] D. Jakubovitz, R. Giryes. Improving DNN robustness to adversarial attacks using Jacobian regularization. In Proceedings of the European Conférence on Computer Vision (ECCV). 514-529, 2018. [7] Q. Li, S. Haque, C. Anil, J. Lucas, R.B. Grosse, J.H.Jacobsen, Preventing gradient atténuation in lipschitz constrained convolutional networks. Advances in neural information processing systems, (2019),32. [8] J. Cohen, E. Rosenfeld, Z. Kolter, Certified adversarial robustness via randomized smoothing. In International Conférence on Machine Learning, (2019), pp. 1310-1320. PMLR. [9] P.Y. Chiang, M. Curry, A. Abdelkader, A. Kumar, J. Dickerson, T. Goldstein, Détection as régression: Certified object détection with médian smoothing. Advances in Neural Information Processing Systems, 33, 2020, pp. 1275-1286.
[10] Thomas S Ferguson. Mathematical statistics: A decision theoretic approach. Academic press, 2014.
Claims
1. A computer-implemented method for training an automatic prediction model of a physical quantity taken from the following quantities: a position of an object in an image, a meteorological quantity such as the temperature, humidity or viscosity of the air, an energy measurement, a quantity measured by a sensor, the method comprising the steps of: - Receiving (401) an initial automatic prediction model of said quantity, - Receiving (402) a set of training data, - Generating (403) a set of noisy training data by adding to each data item of the training data set a randomly drawn noise value, - For each data item of the set of noisy training data, executing (404) the initial automatic prediction model to determine a main prediction of the physical quantity,- Modify the initial model by replacing the main prediction of the physical quantity with a robustified prediction, - Train (405) the modified model from the noisy training data set so that the robustified prediction is equal to a median value of the distribution of the main prediction values provided by the initial model from the noisy training data set, 2. the modified model being trained by minimizing a quantile loss function depending on the difference between a prediction of the physical quantity provided by the initial model from the noisy training data set and the robustified prediction. Method for training an automatic prediction model according to claim 1 further comprising the steps of: - Completing the initial model to further predict at least two certification values defining the bounds of at least one certification interval of the robustified prediction, - Training the completed model from the noisy training data set so that each predicted certification value is equal to a quantile value of the distribution of the main prediction values provided by the initial model from the noisy training data set.
3. Method for training an automatic prediction model according to claim 2 in which the difference between the two quantile values depends on a predefined maximum value of a radius of an adverse attack applied to the training data.
4. Method for training an automatic prediction model according to any one of claims 2 or 3 in which the initial model comprises a main prediction branch (300) of the physical quantity and the completed model further comprises at least one additional prediction branch (301,302) trained to predict the certification values.
5. A method of training an automatic prediction model according to any one of claims 2 to 4 wherein the second quantile value is equal to one minus the first quantile value.
6. A method of training an automatic prediction model according to any one of the preceding claims wherein the modified model is further trained by minimizing a quantile loss function depending on the difference between a prediction of the physical quantity provided by the initial model from the noisy training data set and each respective prediction of a certification value provided by the modified model.
7. Method for training an automatic prediction model according to any one of the preceding claims in which the quantile loss function is defined by the following relationship: ρ y − y ^ τ = τ y − y ^ si y − y ^ ≥ 0 τ − 1 y − y ^ sinon t is a quantile value between 0 and 1, y is a prediction of the physical quantity provided by the initial model from the noisy training data set, ŷis the robustified prediction or a prediction of a certification value provided by the modified model.
8. Method for training an automatic prediction model according to any one of the preceding claims in which the initial model is pre-trained on a first set of training data and the set of noisy training data is obtained by duplicating each data of the first set several times and adding to each data a randomly drawn noise value.
9. Method for training an automatic prediction model according to one of claims 1 to 7 in which the initial model is pre-trained on the set of noisy training data.
10. Method for training an automatic prediction model according to any one of the preceding claims in which the initial model comprises a first part trained to extract a set of characteristics from the input data and a second part comprising at least one prediction branch.
11. Method for training an automatic prediction model according to claim 10 wherein the second part of the modified model comprises a main prediction branch for predicting a robustified prediction of said physical quantity and at least one additional prediction branch of the certification values of said physical quantity, the training parameters of the prediction branches of the modified model being initialized to the training parameters of the main prediction branch of the initial model.
12. Method for training an automatic prediction model according to any one of the preceding claims in which the training data are sets of images and the physical quantity is a position of an object in an image.
13. A method for training an automatic prediction model according to claim 12 wherein the initial model is trained to detect an object in an image and to predict the coordinates of a box enclosing the object.
14. A computer-implemented method for automatically predicting a physical quantity taken from the following quantities: a position of an object in an image, a meteorological quantity such as the temperature, humidity or viscosity of the air, an energy measurement, a quantity measured by a sensor comprising the execution of the modified automatic prediction model, trained by means of the training method according to any one of the preceding claims so as to determine a robustified prediction of said physical quantity and at least two certification values of said physical quantity defining at least one certification interval of said prediction against an adverse attack.
15. Method for automatically predicting a physical quantity according to claim 14 comprising the prediction of several pairs of certification values and the selection of the certification interval having the smallest width and respecting an order relationship such that: the prediction of the lower limit of the certification interval is lower than the prediction of the physical quantity itself lower than the prediction of the upper limit of the certification interval.
16. Method for automatically predicting a physical quantity according to any one of claims 14 or 15 comprising providing a robustness indicator of the robustified prediction to said adverse attack, the robustness indicator being inversely proportional to the width of the certification interval.
17. Method for automatically predicting a physical quantity according to any one of claims 14 to 16 in which the physical quantity is a position of an object in an image and the training data are sets of images.
18. Device for automatic prediction of a physical quantity taken from the following quantities: a position of an object in an image, a meteorological quantity such as the temperature, humidity or viscosity of the air, an energy measurement, a quantity measured by a sensor comprising a calculation unit configured to execute the steps of the method according to any one of claims 14 to 17 and a display interface for displaying the results of the method.
19. Automatic prediction device according to claim 18 wherein the physical quantity is a position of an object in an image and the training data are sets of images.
20. Computer program comprising code instructions for implementing one of the methods according to any one of claims 1 to 17, when said program is executed on a computer.
21. Computer-readable recording medium on which the computer program according to claim 20 is recorded.